Lucene search

K
osvGoogleOSV:CVE-2020-18467
HistoryAug 26, 2021 - 6:15 p.m.

CVE-2020-18467

2021-08-2618:15:07
Google
osv.dev
5
cve-2020-18467
xss
bigtree-cms
tags page
general menu
crafted website name
authenticated post http request
admin panel
security issue

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

24.8%

Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for OSV:CVE-2020-18467